Privacy Policy

Plain text version. Last updated: .

This page carries the same Privacy Policy as the main site, written as plain HTML with no scripts, no tracking and no layout that depends on a modern browser. The styled version has identical wording.

1. Introduction

This Privacy Policy explains how Boundless Missions collects, uses, stores and protects your personal information when you use the KSP add-on, the Discord bot, or this website (collectively, the “Service”). It is written in accordance with the KSP Forum Add-on Posting Rules (Rule 8) which require transparency about data collection in KSP add-ons.

By using the Service and providing your consent through the in-game consent window, you acknowledge that you have read and understood this Privacy Policy. This policy should be read alongside our Terms of Service.

2. Definitions

3. Data We Collect

We collect only the data necessary to provide the Service. The table below lists every category of personal data we process, why we need it, and when it is collected:

Categories of personal data processed by Boundless Missions
Data Purpose When collected
Email address Only when you create a Boundless Missions account on this website. It is your sign-in identity and how an account can be recovered. You can also use the add-on with a Discord account alone and never give us an email address at all. On website sign-up (from Google, or from an email and password)
Boundless username and display name The public handle other players see, and the name a friend request is addressed to. The username is reserved to you for as long as the account exists, so that two accounts cannot share one. When you choose one
Profile picture you upload Shown to other players in the same places a Discord avatar would be. Only if you upload one. On upload
Two-factor enrolment If you turn on two-factor authentication, the shared secret your authenticator app uses and the hashes of your recovery codes. Used only to check the codes you enter when signing in. When you enable two-factor authentication
Discord account link Ties contracts, balance and missions to your identity On linking
Discord profile information Your Discord display name (the nickname you use in the community server, or your account name if you have none), your profile picture and your corporation name and level. Stored so they can be shown to other players inside the add-on (in the player selectors used to send a craft, offer a contract or issue a rescue) and next to the contracts, marketplace listings and auctions you take part in, so people can tell who they are dealing with On linking, and refreshed whenever a list you appear in is drawn
Device identifier A random GUID (no hardware data; see Section 2) that binds your install to your account, so an unapproved device cannot use it On linking and with each request
IP address Connection routing, rate-limiting and abuse prevention Each server request
Gameplay data Vessel telemetry, craft files, part lists and screenshots submitted to contracts or shared When you submit
KSP.log Debugging bug reports and investigating device reports When you file a bug report (your own log, trimmed on your machine before upload), or from the reported device during a device report
Website & community activity Marketplace listings and purchases, likes/dislikes, reports you file, auction bids, contracts you create or accept When you use those features
Moderation records The reason and duration of a service suspension, and the outcome of reports, so enforcement is accountable When a moderation action is taken

4. Consent and Legal Basis

Per KSP Add-on Posting Rule 8.1, we require clear, informed consent before collecting any information. No data is collected until you explicitly opt in.

On first launch the add-on presents a consent window that asks you to:

  1. Read and agree to this Privacy Policy.
  2. Read and agree to the Terms of Service.
  3. Expressly consent to your account, device and gameplay data being collected and transmitted to the Boundless Missions servers.

All three acknowledgments must be checked before any data leaves your game. Your consent is recorded locally and can be revoked at any time (see Section 7).

5. How We Use Your Data

We use the data we collect to:

What other players can see. Boundless Missions is a community service, so part of your Discord profile is visible to other players by design: your display name, your profile picture, your corporation name and your level. If you linked from Discord, your account identifier is your Discord ID, and it is visible to other players wherever you appear — on a marketplace listing, in a player selector, on a friend request — because it is the identifier those features address you by. Your device identifier, your IP address and your KSP.log are never shown to another player, and neither is anything you have not published. What is shown is the same public profile Discord already displays in the community server, and it is shown only to other linked players. If you would rather not appear at all, turning off data sharing (Section 7) or deleting your data (Section 8) removes you from these lists. Separately, and for the opposite case, the add-on can hide other people’s profile pictures and corporation names from your screen (useful when you are streaming or recording) under SettingsPrivacy; while that is on, their pictures are never downloaded rather than merely not drawn.

We do not sell, rent, or share your personal data with third parties for their own use. Your data is never used to profile you, and never used to advertise anyone else’s product: the one promotional use we make is showing crafts you have shared, credited to you, in material about Boundless Missions itself (see above and Section 7 of the Terms of Service). The service providers that process data on our behalf are listed in Section 6.

6. Service Providers

Running the Service relies on a small number of providers that process data on our behalf, under their own published privacy terms:

7. Your Right to Opt Out

In accordance with KSP Add-on Posting Rule 8.2, the add-on provides a built-in way to stop all data collection at any time:

How to opt out: Open the mod toolbar → SettingsData sharing → toggle off. The add-on will immediately stop sending any information to our servers.

Opting out means community features that require server communication (contracts, missions, economy) will become unavailable, but you can continue to use KSP normally.

8. Data Deletion and Your Rights

Per GDPR and KSP Add-on Posting Rule 8.3, you have the Right to Access, Right to Rectification, Right to Restrict Processing, and Right to Erasure regarding your personal data. To exercise these rights or request full deletion of your data at any time:

Upon receiving a valid request we permanently delete, within a reasonable timeframe: your profile (XP, balance, levels, preferences); your account record, including your email address, display name, username and profile picture; your sign-in credential itself; your two-factor enrolment and recovery codes; your session and device bindings, and the device identifiers and IP addresses held with them; your friend list, and your entry in other players' lists; your installed-parts catalog; your achievement progress and marketplace votes; your notification history and pending craft deliveries; and your corporation record. Your marketplace listings are delisted, so nothing further is sold.

Some records are kept, because they are also somebody else's. Contracts and auctions you were party to, and support tickets you opened, remain so that the other person's history stays intact and moderation stays accountable. Craft files another player has already bought stay available to that buyer — deleting your data stops further distribution, but it cannot recall a copy already delivered. Anonymized, aggregated statistics that cannot identify you may also be retained. Ask us if you need any of these looked at individually.

You can also log out every device at any time from the add-on, which immediately revokes every session token issued for your account. Both this control and data deletion remain available even while your account is under a service suspension: a moderation action never takes away your privacy rights.

9. Data Minimisation

In line with KSP Add-on Posting Rule 8.4, we only collect the minimum data necessary to provide the Service:

10. Data Storage and Security

Your data is stored in Google Firebase (Cloud Firestore and Cloud Storage, running on Google Cloud infrastructure) in projects administered by the Boundless Missions team. We take reasonable measures to protect your information from unauthorised access, loss or misuse. However, no system is completely secure and we cannot guarantee absolute security.

Internal access is limited: full account data is accessible only to the project owner, and Discord-server moderators can see only the moderation surface of their own server (listings originating there, reports and tickets filed there). A moderation role in one server grants no visibility into any other.

We retain your data only for as long as it is needed to provide the Service or as required to fulfil the purposes described in this policy. When data is no longer needed, it is deleted or anonymized.

11. The Local Browser Interface

The add-on includes an optional interface that opens in your own web browser instead of drawing windows inside the game. It is off by default and can be enabled or disabled at any time from the mod toolbar under SettingsInterface.

When you enable it, the add-on runs a small web server inside your own computer, on the loopback address 127.0.0.1, and opens your default browser to it. This is worth being precise about:

Cookies. The interface sets one cookie, named gk, scoped to 127.0.0.1. It exists only so the page can prove to your own running copy of KSP that it is the page the game just opened. It is marked HttpOnly and SameSite=Strict, holds a random value with no personal information in it, is not sent to us or to any website, and disappears when you close your browser. It is not used for analytics, advertising or tracking of any kind.

Stored locally. Some preferences the interface uses are saved on your computer in the add-on’s PluginData folder rather than in the browser, for example the players you mark as favourites. These files never leave your machine, and deleting the add-on removes them.

12. Cookies on This Website

This website (as opposed to the local browser interface above) sets exactly two cookies, both strictly functional:

We use no analytics, advertising or tracking cookies. Google reCAPTCHA Enterprise (see Section 6) runs on signed-in pages for abuse prevention and operates under Google’s own privacy policy.

13. Children’s Privacy

The Service is not directed at children under the age of 13. Some countries set a higher minimum age of digital consent, for example up to 16 in parts of the European Economic Area under the GDPR, and where that is the case, the higher age applies to you. We do not knowingly collect personal data from anyone below the age that applies in their country. If you believe a child has provided us with personal data, please contact us through the Discord server or at either email address in Section 16 and we will promptly delete it.

14. Open Source and Transparency

All source code for Boundless Missions is publicly available under the GNU General Public License v3.0 (GPL-3.0). You are free to inspect the code to verify exactly what data is collected and how it is transmitted. You can also modify and redistribute the code in accordance with that licence.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, for material changes, notify users through the Discord server, this website and/or an in-game prompt. For material changes the add-on additionally stops transmitting any data and re-presents the consent window: nothing further leaves your game until you have read and accepted the updated policy. Continued use of the Service after changes constitutes acceptance.

16. Contact

Questions about this Privacy Policy? Reach out to us via email at legal@boundlessmissions.com. For account help, bug reports and anything else, email support@boundlessmissions.com, ask in the Boundless Missions Discord server, or open an issue on our GitHub repositories.